Impact
An out‑of‑bounds write flaw stems from improper input validation in Samsung Pass on Samsung mobile devices. When a local privileged attacker delivers crafted input to versions older than 5.2.10.3, the service writes memory beyond the intended buffer, potentially allowing the attacker to execute arbitrary code and elevate privileges on the device. The description does not indicate consequences beyond this privilege escalation.
Affected Systems
Samsung Pass on Samsung mobile devices. Versions prior to 5.2.10.3 are vulnerable; releases 5.2.10.3 and later contain the fix.
Risk and Exploitability
The CVSS score of 6.8 signifies moderate severity, while an EPSS score below 1% reflects a very low but nonzero likelihood of exploitation. This vulnerability is not listed in CISA KEV. Exploitation requires local privileged access to supply the malicious input; no remote or network attack vector is described.
OpenCVE Enrichment